Privacy and security
Built so that less data moves, not more.
Most security programmes try to protect data after it has been shared. OpenCheque starts earlier: the record never leaves its custodian, so there is far less to protect.
By design
Six commitments.
Answers only
A fixed, narrow answer crosses the boundary. Bills, statements, histories and source records stay where they are.
The custodian decides
Providers approve each offering: the exact question, who may ask, for what purpose and in which territory. They can pause it or lower its rate at any moment.
Consent through trusted channels
When permission is needed, the customer gives it in the app or site of the institution that already holds their data. No new wallet, password or enrolment.
One purpose, one use
A permission covers the request it was given for. It is not quietly reused for a second query, a new recipient or ongoing monitoring.
No central customer graph
OpenCheque does not build a global customer identifier or pool member data. Matching happens at the custodian, against its own records.
An audit trail both sides can read
Every request, permission, release and correction is recorded, so an answer can be traced and challenged later.
Honest provenance
Every answer says how it was obtained.
Not all evidence is equal, and an exchange should never blur the difference. Each offering declares its minimum evidence class, and a stronger class is never silently replaced by a weaker one.
PROVIDER_SIGNEDAPI_OBSERVEDHUMAN_ATTESTEDDelivery
Two delivery routes, chosen by the provider.
The provider’s approved profile selects the route. A requesting institution cannot downgrade it to save time or cost.
Managed minimal-answer delivery
OpenCheque connects to the custodian, validates the minimal response and makes it available to the requester. We can see that answer, and nothing behind it. It is encrypted in transit and at rest, access-controlled, retained briefly, and never used for secondary analytics or model training.
Private delivery
Where a product demands that the intermediary sees nothing, the custodian encrypts the answer directly to the requesting institution. OpenCheque coordinates the exchange and handles only restricted metadata.
For the people behind the data
Clear requests. Real choices.
A permission screen names the parties, the purpose, exactly what will be answered and what will not be shared. Refusing is never treated as a sign of fraud.
- One clear screen per request, not a modal for every check.
- No pre-ticked boxes, no silent approval, no timeout that counts as consent.
- Withdrawal through the customer’s usual account, without installing anything.
- No repeated prompt campaigns after someone declines.
- Protected investigations follow a separate, separately approved route and never leak into customer notifications.
Security review
Bring your risk, legal and security teams.
We are happy to walk through the consent model, delivery profiles, evidence classes and audit trail in detail with the people who have to sign it off.
Arrange a reviewTrust isn’t a feature.
OpenCheque
It’s infrastructure.